Arno's IPTABLES Firewall Script 1.8.8c
Details
| Size: | 90K |
| Last Update: | 2008-04-19 23:33:08 |
| OS Support: | Linux |
| License/Program Type: | GPL (GNU General Public License) |
| Publisher: | Arno van Amersfoort |
| Price: | $0.00 |
Description:
Arno's IPTABLES Firewall Script 1.8.8c is software developed by Arno van Amersfoort.
Arno's IPTABLES firewall script was initially written because I needed to protect my single-homed Linux machine at work. I wrote it at the time I couldn't find any script that really satisfied my needs except for one that was written by a guy called 'Seven'.
I helped him for several months with the work on his script by suppling patches, reporting bugs etc. In this period I was fortunately also able to master scripting for iptables myself because soon Seven discontinued his work, I never got to even talk to the guy ever again. At that point I decided to continue his work, or actually I started my own branch based on his script.
In the summer of 2002 I finally got an ADSL connection at home. Initially I used the iptables firewall that came with the great ADSL4LINUX-package (http://www.adsl4linux.nl). But it didn't take me long to come to the conclusion that their iptables firewall lacked important features like port-forwarding and flexbility with "trusted hosts" etc.
I also didn't like the fact that I had to use a different firewall for my home machine and the machine at work. This made me decide to use some of the ADSL4LINUX knowledge to implement ADSL support.
By now (about 1 year later as of writing) there are only few remnants left of Seven's original script and many, many, many improvements were applied. One major improvement is the ADSL and NAT support (Check the 'features' page with the specifiations of my firewall). For version 2 (alpha) I plan to completely rewrite to script to make it more flexible and to increase the usability for others.
Here are some key features of "Arno s IPTABLES Firewall Script":
Very secure stateful filtering firewall
Both kernel 2.4 & 2.6 support
It can be used for both single- and multi(eg. dual)-homed boxes
Masquerading (NAT) and SNAT support
Multiple external (internet) interfaces
Support multiroute NAT & SNAT (load balancing over multiple (internet) interfaces)
Port forwarding (NAT)
Support MAC address filtering
Support for DSL/ADSL modems
Support for PPPoE, PPPoA and bridging modem setups
Support for static and ISP assigned (DHCP) IPs
Support for (transparent) proxies
Full support for DMZ's and DMZ-2-LAN forwarding. You can also use it to isolate your eg. wireless LAN.
(Nmap)(stealth) portscan detection
Protection against SYN-flooding (DoS attacks)
Protection against ICMP-flooding (DoS attacks)
Extensive user-definable logging with rate limiting to prevent log flooding
Includes options to optimize your throughput
User definable open ports, closed ports, trusted hosts, blocked hosts etc.
Log & protection options are both highly customizable
Support for custom iptables rules in a seperate file
It can be used with chkconfig runlevel system (eg. RedHat/Fedora)
Main focus on TCP/UDP/ICMP but additional support for ALL IP protocols
It works with Freeswan IPSEC (VPN) & SSH Sentinel (http://www.freeswan.org) (+virtual IP's)
It works with PoPTop PPTP (http://www.poptop.org)
It works with UPnP
DRDOS protection/detection (experimental)
It's easy to configure
And much more.
What's New in This Release:
A bug in the MAC_FILTER was fixed.
The MAC/blocked hosts rules were slightly changed.
The number of MAC addresses and blocked hosts loaded is now shown.
Minor changes were made.
Arno's IPTABLES Firewall Script 1.8.8c supports english interface languages and works with Linux.
Downloading Arno's IPTABLES Firewall Script 1.8.8c will take several seconds if you use fast ADSL connection.
0 comments
Add to
Arno's IPTABLES Firewall Script 1.8.8c Version History
Related Software
|
|
From category: Desktop-Widgets |
| All System Info is desktop widgets software developed by revolutionist. All System Info is a system info SuperKaramba theme. Simple english version... It shows: System Info CPU usage... |
|
|
From category: Libraries |
| Freedaisy 0.0.1 Alpha1 is libraries software developed by Alexis. Freedaisy is a free implementation of Daisy book standard for allowing MP3 files to be indexed using (X)HTML and SMIL. Daisy... |
|
|
From category: Themes |
| Arena is a a nice and simple GTK theme for GNOME that uses the Clearlooks engine.... |
|
|
From category: Networking |
| Egressor 1.0 is networking software developed by MITRE. MITRE has released a freeware tool that allows a company to check the configuration of their Internet point-of-presence router. Egressor will... |
|
|
From category: File-managers |
| mp3ql is an application for browsing, organizing and tagging large collections of mp3 files.... |
|
|
From category: Backup |
| afbackup 3.5 is backup software developed by Albert Fluegel and Jalon Q. Zimmerman. afbackup project is a client-server backup system offering several workstations a centralized backup to special b... |
|
|
From category: Tools |
| DiskSearch 1.1.3 is tools software developed by Stefan Saring. DiskSearch project is a tool for searching for files on all your removable media disks (e.g. CD&039;s, ZIP disks or backup tapes). \... |
|
|
From category: Other-Tools |
| Devenv is a simple yet powerful command-line utility that allows software development teams set and validate their common development environment. Common development environment is a set of directorie... |
|
|
From category: Libraries |
| Better String Library 07222006 is libraries software developed by Paul Hsieh. Better String Library is an abstraction of a string data type which is superior to the C library char buffer string typ... |
|
|
From category: Bug-Tracking |
| BugPort 1.147 is bug tracking software developed by INCOGEN. The BugPort system is an open-source, freely available, web-based system to manage tasks and defects throughout the software development... |
|
|
From category: Libraries |
| tree.hh is a general purpose templated tree class for C++ in the spirit of the STL, and compatible with the STL algorithms.... |
|
|
From category: Emulators |
| MSPsim is a Java-based instruction level emulator of the MSP430 series microprocessor.... |
|
|
From category: Monitoring |
| Battery OSD 0.1 is monitoring software developed by WhiteTiger. Battery OSD is a program that displays battery information and other types of system information on screen with the OSD library. \... |
|
|
From category: System-Administration |
| Afick Webmin module 1.5.3 is system administration software developed by Eric Gerbier. Afick is a security tool, very close from the well known tripwire. Afick Webmin module allows to monitor the c... |
Leave a comment